Ransomware Series: Multi-Technique Microsoft Defender Tampering Before Encryption
Detects multiple methods of tampering with Windows Defender security controls within a short time window. This includes PowerShell commands to modify Defender preferences (e.g., disabling Real-time Monitoring or adding exclusions), modifications to Defender-related registry keys, and attempts to stop or disable the WinDefend service.
Microsoft Sentinel (KQL)

